top of page
perceptive_background_267k.jpg

Qilin Ransomware Turns South Korean MSP Breach Into 28-Victim 'Korean Leaks' Data Heist

Published:

26 november 2025 om 14:31:00

Alert date:

5 december 2025 om 08:03:22

Source:

thehackernews.com

Click to open the original link from this advisory

Qilin ransomware group conducted a sophisticated supply chain attack targeting South Korea's financial sector through a Managed Service Provider (MSP) breach. The attack resulted in 28 victims in what's being called the 'Korean Leaks' data heist. The operation combined Qilin's Ransomware-as-a-Service (RaaS) capabilities with potential involvement from North Korean state-affiliated actors, specifically Moonstone Sleet. The attack leveraged the MSP infrastructure to reach multiple downstream clients, demonstrating the amplified impact of supply chain compromises in the financial sector.

Technical details

Mitigation steps:

Affected products:

MSP Infrastructure

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page